PT-2023-23663 · Sailpoint · Identityiq

Published

2023-05-31

·

Updated

2023-06-12

·

CVE-2023-32217

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IdentityIQ versions 8.0 through 8.0p5 IdentityIQ versions 8.1 through 8.1p6 IdentityIQ versions 8.2 through 8.2p5 IdentityIQ versions 8.3 through 8.3p2
Description The issue allows an authenticated user to invoke a Java constructor with no arguments or a Java constructor with a single Map argument in any Java class available in the IdentityIQ application classpath.
Recommendations For IdentityIQ versions 8.0 through 8.0p5, update to version 8.0p6 or later. For IdentityIQ versions 8.1 through 8.1p6, update to version 8.1p7 or later. For IdentityIQ versions 8.2 through 8.2p5, update to version 8.2p6 or later. For IdentityIQ versions 8.3 through 8.3p2, update to version 8.3p3 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-32217

Affected Products

Identityiq